Livewire Vulnerability Exposes Millions of Laravel Apps to Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability in Laravel’s Livewire framework has been discovered that could expose millions of web applications to remote code execution (RCE) attacks.  The flaw, designated as CVE-2025-54068, affects …

New KAWA4096’s Ransomware Leverages Windows Management Instrumentation to Delete Shadow Copies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new ransomware strain named KAWA4096 has emerged in the cybersecurity landscape, showcasing advanced evasion techniques and borrowing design elements from established threat actors. Named after the Japanese word …

CoinDCX Hacked – $44.2 million Wiped off From the Platform

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

India’s second-largest cryptocurrency exchange, CoinDCX, confirmed a sophisticated security breach on July 19, 2025, resulting in approximately $44.2 million being stolen from the platform. This incident marks another significant cyberattack …

HPE Warns of Aruba Hardcoded Credentials Allowing Attackers to Bypass Device Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Hewlett Packard Enterprise (HPE) Aruba Networking Instant On Access Points could allow attackers to bypass device authentication mechanisms completely.  The vulnerability, tracked as CVE-2025-37103, stems from …

Microsoft Released Emergency Security Update to Patch Critical SharePoint 0-Day Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has issued an urgent security advisory addressing critical zero-day vulnerabilities in on-premises SharePoint Server that attackers are actively exploiting.  The vulnerabilities, assigned as CVE-2025-53770 and CVE-2025-53771, pose immediate risks …

New PoisonSeed Attack Let Attackers Trick Users into Scanning a QR Code with an MFA Authenticator

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new attack technique compromises Fast IDentity Online (FIDO) key authentication by exploiting cross-device sign-in features.  The PoisonSeed attack group has developed a method to downgrade FIDO key protections …

PoC Exploit Released for Critical NVIDIA AI Container Toolkit Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical container escape vulnerability has emerged in the NVIDIA Container Toolkit, threatening the security foundation of AI infrastructure worldwide. Dubbed “NVIDIAScape” and tracked as CVE-2025-23266, this flaw carries a …

New 7-Zip Vulnerability Enables Malicious RAR5 File to Crash Your System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical memory corruption vulnerability in the popular file archiver 7-Zip has been discovered that allows attackers to trigger denial of service conditions by crafting malicious RAR5 archive files. The …

Weekly Cybersecurity Newsletter: Chrome 0-Day, VMware Flaws Patched, Fortiweb Hack, Teams Abuse, and More

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

It’s been a busy seven days for security alerts. Google is addressing another actively exploited zero-day in Chrome, and VMware has rolled out key patches for its own set of …

Grafana Vulnerabilities Allow User Redirection to Malicious Sites and Code Execution in Dashboards

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two significant Grafana vulnerabilities that could allow attackers to redirect users to malicious websites and execute arbitrary JavaScript code.  The vulnerabilities, identified as CVE-2025-6023 and CVE-2025-6197, affect multiple versions of …